Data Processing Addendum

Effective Date: Nov 3, 2025

1. Definitions


2. Processing of Customer Personal Data

2.1 Roles of the Parties

2.2 Customer Obligations

2.3 Tembo Obligations


3. Details of Data Processing

3.1 Subject Matter and Duration

3.2 Nature and Purpose of Processing

3.3 Categories of Personal Data

3.4 Categories of Data Subjects


4. Security

4.1 Security Measures

4.2 Personnel Security


5. Subprocessing

5.1 Authorized Subprocessors

5.2 Subprocessor Obligations

5.3 Changes to Subprocessors


6. Data Subject Rights


7. Personal Data Breach

7.1 Notification

7.2 Cooperation


8. Data Protection Impact Assessment


9. Deletion and Return of Data


10. Audit Rights


11. International Data Transfers

11.1 Transfer Mechanisms

11.2 Standard Contractual Clauses

11.3 UK and Swiss Transfers

11.4 Infrastructure Location


12. General Terms

12.1 Order of Precedence

12.2 Liability

12.3 Governing Law

12.4 Severability


13. Contact